Home Privacy Policy

Privacy Policy

Privacy Policy

 

Policy pursuant to European Regulation no. 2016/679 (GENERAL DATA PROTECTION REGULATION – GDPR)


DATA CONTROLLER
RIVERCLACK SPA with headquarters in Via Belvedere 78, 37026 Pescantina (VR), Italy, Tax Code and VAT T00251170239 (hereafter: “Owner”).


1) PURPOSES AND METHODS OF TREATMENT

  • To address your request for a quote or information regarding an ongoing contract;
  • To comply with obligations envisioned by regulations;
  • If necessary, to ensure, practice or defend the Owner’s rights in court;
  • To view web pages and take advantage of services potentially provided within the site (http://www.riverclack.com (hereafter: The Site);
  • To send advertising and informational material, carry out sales or placement activities of products or services, send commercial information, carry out interactive trade communications.


The processing of personal data is carried out by means of operations listed under Article 4 of this Privacy Policy and Article 4 no. 2) GDP, namely: collection, registration, conservation, consultation, elaboration, modification, selection, extraction, evaluation, use, interconnection, blocking, communication, deleting and destruction of data. Personal data are subjected to both paper, electronic and/or automated processing by authorized parties in compliance with the principles of lawfulness, purpose limitation and data minimization.


2) LEGAL BASIS OF TREATMENT

Contractual purpose: execution of a contract to which you are a party

  • Legal obligations: need to fulfill legal obligations;
  • Rights of the owner: legitimate interest;
  • Functioning of the site: legitimate interest;
  • Promotional and marketing purposes: your explicit consent.

 

3) PERSONAL DATA RETENTION PERIOD

  • Contractual purpose, legal obligations: for the entire contractual duration and for 10 years after termination;
  • Owner rights: in case of legal dispute, for its the entire duration, until the expiration of the appeal deadlines;
  • Site operation: for the entire duration of the browsing session on the site;
  • Promotional and marketing purposes: 12 months from the end of the contractual relationship.


Once the retention periods indicated above have expired, your personal data will be destroyed, deleted or made anonymous, compatibly with the technical cancellation and backup procedures.

 

4) PROCESSED PERSONAL DATA TYPE

  • Personal data processed for contractual purposes - legal obligations – owner rights - debt collection: Personal data, contact data, administrative-accounting data;
  • Personal data processed for the functioning of the site: During their normal operation, the computer systems and software procedures which are employed in the functioning of the site acquire some personal data of which transmission is implicit in the use of Internet communication protocol. This kind of information isn't gathered to be associated with identified interested parties, but, by its very nature, could help identify the site's users through processes and associations with the data stored by the owner or third parties. Notably, IP addresses or domain names of the users who connect to the site, URI (Uniform Resource Identifier) addresses of the required resources, request time, the method adopted in submitting the request to the server, the obtained file size in response, the number code stating response status given by the server (success, error, ecc.), other parameters relative to the operating system and the user's computing environment, the information relative to the user's behavior on the site, their visited/searched pages in order to select and make specific ads for the site user and the data relative to the website navigation behavior through cookies for example;
  • Processed personal data for communication and marketing purposes: contact details.

 

5) MANDATORY DATA PROVISION

Personal data provision already mentioned in points 4.1 and 4.2 is mandatory.
The refusal to provide the aforementioned personal data does not allow using the services/contents offered by the site.
Data provision for the purposes referred to in point 4.3 is optional.

 

6) DATA RECIPIENTS

Data may be processed by external parties acting as Data Controllers such as, for example, supervisory and control authorities and bodies and in general public or private entities entitled to request the data, as well as persons, companies, associations or professional firms, which provide assistance and consultancy activities. The data may also be processed, on behalf of the Data Controller, by external parties designated as data controllers pursuant to art. 28 of the GDPR, who are given adequate operational instructions. These subjects are essentially included in the following categories:
a. companies that offer website and information system maintenance services;
b. companies that carry out management and maintenance services on the Data Controller's database.
Personal data will not be disclosed, but may possibly be transmitted to Public Authorities who may specifically request them from the Data Controller for administrative or institutional purposes, in accordance with the current national and European legislation provisions.

 

7) PERSONAL DATA TRANSFER

To achieve the aforementioned purposes, the Data Controller may rely on software solutions providers, web applications and storage services which are also provided via cloud computing systems on servers that may be located in non-EU countries.
In case of any personal data getting transferred to these countries, in the absence of an adequacy decision from the European Commission, personal data transfers will only be possible when proper guarantees of contractual or pactional nature are provided by the Data Controller and the Managers involved, including binding corporate rules and standard contractual data protection clauses. Transfer of your Personal Data to third countries outside the European Union (in the absence of an adequacy decision or other proper measures as described above) will be carried out only according to your explicit approval or in the cases provided for in the GDPR and will be in any case managed in your interest.

 

8) ENTITIES AUTHORIZED TO PROCESS

Your data may be processed the Data Controller's corporate functions employees who are responsible to pursue the purposes indicated above; accordingly, they have received adequate operating instructions and they have been expressly authorized to process data.
Data collected while browsing the Site (referred to in point 4.2) may be processed by employees, Owner collaborators or external parties, as data processors and managers, who carry out technical and organizational website tasks on behalf of the Owner.

 

9) YOUR RIGHTS AS A DATA SUBJECT TO THE PROCESSING - COMPLAINT WITH THE SUPERVISORY AUTHORITY

Under certain conditions you have the right to ask the Owner:
 

  • Access to your personal data;
  • The copy of the personal data you have provided to us (so-called portability);
  • The rectification of the data in our possession;
  • The deletion of any data for which we no longer have any legal basis for processing;
  • Opposition to processing where required by applicable law;
  • The revocation of your consent, in the event that the processing is based on consent;
  • Limitation of the way in which we process your personal data, within the limits established by the legislation for the protection of personal data.


If you wish to lodge a complaint pursuant to art. 77 GDPR to the competent supervisory authority based on your habitual residence, place of work or place of violation of your rights; for Italy, the person responsible is the Guarantor for the protection of personal, who can be contacted via the website contact details http://www.garanteprivacy.it.
The exercise of these rights is subject to some exceptions aimed at safeguarding public interest (for example the prevention or identification of crimes) and our interests (for example the maintenance of professional secrecy). If you happen to exercise any of the aforementioned rights, it will be our responsibility to verify that you are entitled to exercise it and we will give you feedback.


10) DATA SECURITY

Your personal data will be processed with automated tools in the strictly necessary time to achieve the purposes for which they were collected and in compliance with the principle of necessity and proportionality, avoiding processing personal data if the operations can be carried out through the anonymous use of data or through other methods. We have adopted specific security measures to prevent personal data loss, illicit or incorrect use and unauthorized access but please do not forget how essential it is for the security of your data that your device is equipped with tools such as constantly updated antivirus and that the provider providing you with Internet connection guarantees secure transmission of data through firewalls, anti-spamming filters and similar safeguards.

 

11) OWNER’S CONTACT DETAILS

To exercise the rights referred to in point 8, you can contact the owner at the following addresses: RIVERCLACK SPA with registered office in Via Belvedere 78, 37026 Pescantina (VR), Italy, Fiscal Code. and Part. VAT IT00251170239, T +39 045 773 21 77, F +39 045 773 29 70, privacy@iscom.it

 

Versatile, Easy-to-Install, Long-Lasting, Sustainable

More than

18.4 Mil Sqm

Installed in over 35 Countries All Around the World.